Is your website secure?
Type your address and see in seconds whether your site uses HTTPS properly, sends the security headers browsers expect, and runs software with known security holes.
- •HTTPS, certificate and redirect
- •Security headers and cookies
- •Outdated WordPress and jQuery
Why it matters
Browsers warn visitors
A broken certificate or insecure files show a warning that sends customers away.
Old software gets hacked
Most hacked small business sites run an outdated WordPress, theme or plugin.
Google prefers safe sites
HTTPS is a ranking signal, and hacked sites can be removed from search results.
Small fixes, big effect
Most of what this check finds is fixed in an hour by someone who knows where to look.
What we check
- HTTPS works and the certificate is valid
- Visitors on http are sent to https
- Security headers: HSTS, CSP, clickjacking, MIME sniffing, referrer
- Cookies marked Secure and HttpOnly
- Insecure http files on a secure page
- Outdated WordPress or jQuery versions
Questions
Is it safe to check any website?
Yes. We only read what every visitor's browser receives anyway. We never try to break in or look for hidden files.
My score is low. Have I been hacked?
Not necessarily. A low score means your site is easier to attack than it should be. Fix the red items first.
Does a perfect score mean my site is safe?
No outside check can promise that. Strong passwords, backups and updates for themes and plugins matter just as much.
Can you fix what it finds?
Yes. Security fixes, updates and backups are part of my monthly care plan, for WordPress and custom sites.
Want your website kept safe and up to date?
You get a reply within one working day with a clear scope and a price. No sales team, you talk to the engineer who builds it.
